The complete guide to redacting candidate CVs

Almost every recruitment agency redacts CVs, but surprisingly few have a redaction process. In most of the agencies we work with, the decision about what to strip out of a candidate's CV before it goes to a client sits with whichever recruiter happens to be sending it, on whatever day they're sending it, with whatever time they have left before the hiring manager's deadline. One consultant removes the phone number and email. Another also removes the home address and the photo. A third forgets the LinkedIn URL in the footer and the candidate's name in the file title.

None of that is carelessness. It's what happens when an important task is treated as a manual tidy-up rather than a defined step in delivery. We'd argue that candidate CV anonymization has quietly become one of the most consequential things an agency does, because it now sits at the meeting point of three pressures that weren't nearly as sharp a few years ago: data protection, fairness in hiring, and the commercial protection of the agency's own work. This guide sets out what good redaction looks like, where personal data tends to hide, and how to make it consistent without slowing client submission down.

Why redaction matters more than it used to

The first pressure is regulatory. Under the GDPR's data minimisation principle, personal data should be "adequate, relevant and limited to what is necessary" for the purpose it's processed for. When an agency sends a CV to a client, the purpose is to help that client decide whether to interview the candidate. A home address, a date of birth or a personal mobile number rarely serves that purpose, which makes sharing them by default hard to justify. The UK's ICO makes a related point in its guidance on recruitment and selection, noting that recruitment data can include sensitive details about health, diversity or criminal convictions. And with the EU AI Act classifying AI used in recruitment and candidate evaluation as high-risk, with obligations on data quality and human oversight for the agencies that deploy it, the question of what candidate data flows where is only going to get more attention.

The second pressure is fairness. The evidence that identifying details shape hiring decisions is long-standing. Bertrand and Mullainathan's field experiment found that otherwise identical CVs received significantly fewer callbacks when they carried names perceived as Black rather than white. More recently, research from Harvard Business School's Katherine Coffman and colleagues found that blinding demographic information narrowed the gender and age gap in who applied for roles by around 25%. Redaction isn't a complete answer to bias, and we'll come back to that, but it removes some of the most obvious triggers at the point where a hiring manager first forms a view.

The third pressure is commercial, and it's the one agencies talk about least in public. A CV with a full name, a phone number and a LinkedIn link attached is a CV a client can act on without you. Controlling what's shared, and when, is part of protecting the value of the work that went into finding the candidate.

Redaction, pseudonymisation and anonymisation are not the same thing

The language around this gets used loosely, so it's worth being precise. Redaction is the act of removing or obscuring specific information from a document. Pseudonymisation is replacing identifying details with something else, such as "Candidate A" or a reference number, while the agency keeps the means to link the profile back to the real person. Anonymisation, in the strict GDPR sense set out in Recital 26, means the data can no longer be linked to an individual by anyone using means reasonably likely to be used.

In practice, almost every anonymized resume an agency sends to a client is actually pseudonymised. The agency still knows who Candidate A is, and the combination of a specific job history, employer names and dates can often identify someone in a small market. That matters because pseudonymised data is still personal data and still needs to be handled as such. We'd encourage agencies to use "redacted" or "anonymised for submission" in their client-facing language, and to treat the underlying data with the same care they would an unredacted CV.

What to remove: a practical framework

We find it most useful to think about personal data removal in three tiers, and to decide each tier as an agency-wide policy rather than a consultant-by-consultant judgement call.

Always remove

  • What it covers: Personal email, phone numbers, home address, photo, date of birth or age, national ID or passport numbers, marital status, dependants, personal social media links
  • Default: Remove for every client submission

Remove to reduce bias

  • What it covers: Full name (replace with an identifier), gendered pronouns in summaries, nationality and place of birth (unless right to work is relevant), graduation and school-leaving years that signal age, hobbies or memberships that reveal religion, politics or health
  • Default: Remove by default, with documented exceptions by client or role

Context-dependent

  • What it covers: Current employer name in confidential searches, referees' names and contact details, salary history, specific project or client names under NDA
  • Default: Decide per brief, recorded against the role

The value of writing this down isn't the list itself. It's that the decision is made once, deliberately, and then applied every time, rather than being re-made under deadline by whoever is sending the CV.

Where personal data hides

The most common redaction failures we see aren't in the body of the CV. They're in the places nobody thinks to check.

File names are the classic example. A beautifully anonymised profile titled "Firstname_Lastname_CV_final.pdf" has undone all the work before it's opened. Document headers and footers often carry contact details that don't show in a quick scroll. File metadata, the author field and document properties, can contain the candidate's name or the name of the recruiter who originally received it. Hyperlinks can display one thing and point to another, so a link that reads "Portfolio" may resolve to a personal domain with the candidate's full name in it. Text embedded in images, such as a scanned signature or a logo with a name in it, won't be caught by a text search at all.

And then there's the most persistent problem in document redaction generally: drawing a black box over text in a PDF doesn't remove the text underneath. It can often be copied, searched or revealed by anyone who knows where to click. Proper redaction removes the data from the document. Covering it up only hides it from the person looking.

How to build redaction into client submission

The agencies that do this well have stopped treating redaction as a separate task and started treating it as a property of the output. In our experience, the process that works looks something like this.

Set the policy once. Agree the three tiers above at agency level, with named exceptions for particular clients or role types. Store those rules somewhere every recruiter's tools can apply them, not in a PDF on the intranet.

Rebuild, don't edit. The most reliable way to redact a CV is to parse the original into structured data and generate a new document from it, including only the fields your policy allows. That eliminates hidden metadata, stray headers and the black-box problem in one step, because the original file never leaves the building.

Make the template do the work. If your client-ready template simply doesn't have a field for a home address or a date of birth, it can't be included by accident. Redaction becomes a design decision rather than a checklist.

Control how profiles are shared. A redacted CV sent as an email attachment can still be forwarded, downloaded and stored anywhere. Sharing profiles through a controlled space, where you can see who has accessed what, gives you far better visibility than an inbox ever will.

Keep humans in the loop. Automated redaction should be checked, particularly for the context-dependent tier. A quick review before submission catches the confidential client name in a project description that no rule could have anticipated.

Redaction and AI: a word of caution

There's an irony we see more and more often. Recruiters, keen to save time, paste a candidate's full CV into a public AI assistant and ask it to remove the personal details. The redacted output may be fine, but the unredacted original has already been shared with a third-party tool the agency may have no agreement with. Microsoft and LinkedIn found that 78% of AI users bring their own tools to work, and recruitment is no exception. We don't think the answer is to ban AI. It's to give recruiters a sanctioned tool that handles redaction inside a governed environment, so the shortcut isn't needed.

It's also worth being realistic about what redaction can and can't do for fairness. It reduces bias at the shortlisting stage. It does nothing for an unstructured interview, a vague brief or a hiring manager who goes looking for the candidate online. Redaction works best as one part of a broader commitment to structured, evidence-based assessment, not as a substitute for it.

Where Allsorter Nexus fits

Candidate presentation has always been Allsorter's core strength. For four years our formatting engine has helped more than 400 recruitment agencies turn messy source CVs into consistent, branded profiles, and the rebuild-not-edit approach described above is exactly how it works: the original document is parsed, and a new client-ready profile is generated from the structured data.

Allsorter Nexus brings that engine into a wider, chat-driven recruitment workflow. Candidate presentation in Nexus means redaction rules can be applied as part of producing the profile, rather than as a manual step afterwards, and the Hiring Manager Portal gives clients a single place to review shortlisted candidates and leave feedback, rather than a trail of email attachments. Both products are covered by our ISO 27001 certification and built to GDPR standards. The result is that compliant client submission stops depending on which recruiter is sending the CV and starts depending on a policy your whole agency has agreed.

Book a demo to see how Nexus handles candidate presentation and client submission in one workflow.

A quick redaction checklist

  • Agency-wide redaction policy agreed, with documented exceptions by client or role
  • Profiles rebuilt from parsed data rather than edited from the original file
  • File names use a candidate identifier, never a real name
  • Headers, footers, metadata and hyperlinks checked or regenerated
  • No black-box "redaction" on PDFs
  • Profiles shared through a controlled portal rather than email attachments where possible
  • A human check before every client submission
  • Unredacted CVs kept within your ATS and approved tools only

Frequently asked questions

What is candidate CV anonymization?

It's the process of removing or replacing personal and identifying information on a candidate's CV before it's shared with a client or hiring manager. In practice most agency anonymisation is pseudonymisation, because the agency can still link the profile back to the candidate.

What should recruiters remove from a CV before client submission?

At a minimum, personal contact details, home address, photo, date of birth and identification numbers. Many agencies also remove names, nationality, graduation years and personal interests to reduce bias, and decide per brief on details such as current employer and referees.

Does anonymising CVs reduce hiring bias?

Research suggests it helps at the shortlisting stage by removing obvious demographic triggers. It works best alongside structured interviews and clear assessment criteria.

Is drawing a black box over text in a PDF enough to redact it?

No. The underlying text often remains in the file and can be copied or revealed. Proper redaction removes the data, ideally by generating a new document that never contained it.